skills/golang/golang-security/SKILL.md
Secure Go backend services against common vulnerabilities. Use when implementing input validation, crypto, or SQL injection prevention in Go.
npx skillsauth add hoangnguyen0403/agent-skills-standard golang-securityInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
go-playground/validator or google/go-cmp for struct validation.bluemonday for HTML sanitization.crypto/rand, NEVER math/rand for security-sensitive operations (tokens, keys, IVs).golang.org/x/crypto/argon2). NOT use bcrypt (weaker) or MD5/SHA1 (insecure). Recommended params: time=1, memory=64MB, threads=4.crypto/aes with GCM mode for authenticated encryption.$1, $2 placeholders with database/sql or ORM (GORM, sqlx).fmt.Sprintf().golang-jwt/jwt v5+. Enforce RS256 (preferred) or HS256. Reject none and symmetric algorithms for multi-service auth. Validate alg, iss, aud, exp claims.gorilla/sessions.godotenv or Kubernetes secrets.math/rand for Security: RNG predictable. Use crypto/rand.fmt.Sprintf() for SQL: Causes SQL injection. Use placeholders.argon2id exclusively.testing
Infer the requesting operator's technical fluency from message content (never ask directly) and adapt register — business, hybrid, or technical — across SDLC workflow output. Use when starting sdlc, brainstorm-feature, plan-feature, verify-work, publish-notes, or session-report, or whenever a request's phrasing signals a non-technical or cross-stack operator.
documentation
Define transaction boundaries, locking, and consistency guarantees for multi-step writes. Use when designing atomic operations, retries, idempotency, or concurrent write behavior.
development
Design relational or document schemas from access patterns, cardinality, and lifecycle. Use when modeling entities, choosing embed vs normalize, or shaping schema boundaries before implementation.
data-ai
Diagnose database latency with explain plans, index ownership, and query-shape review. Use when a query is slow, an index is missing, or scans and N+1 patterns appear.